New Calendly-Inspired Phishing Attack Aims to Steal Google Workspace Credentials
A recent phishing campaign is exploiting Calendly-branded job invitations to compromise Google Workspace and Facebook Business accounts, particularly targeting ad management platforms utilized by agencies and large companies.
A recent phishing campaign is exploiting Calendly-branded job invitations to compromise Google Workspace and Facebook Business accounts, particularly targeting ad management platforms utilized by agencies and large companies.
The campaign, identified by Push Security, employs Attacker‑in‑the‑Middle (AiTM) and Browser‑in‑the‑Browser (BITB) techniques to avoid detection and maximize unauthorized access.
Initially detected after a targeted email attack on a Push customer’s Google Workspace account, the attackers prioritize gaining control of accounts managing digital advertising.
The phishing attempt was disguised as a job opportunity from LVMH, using an email address impersonating the group’s talent acquisition department.
The phishing attack uses generative AI and web-scraped data to craft convincing communications. The phishing link is delivered after initial email exchanges, embedded as a link resembling a Calendly invite, designed to bypass email security systems.
The phishing attempt was disguised as a job opportunity from LVMH, using an email address impersonating the group’s talent acquisition department.
Victims are redirected to a counterfeit Calendly landing page, complete with CAPTCHA, which then presents a "Continue with Google" option. This leads to an AiTM phishing page that mimics the real Google login process, but with Calendly branding.
Conditional loading and domain-based checks are employed to ensure only targeted email domains can progress, blocking unauthorized domains from observing the credential-harvesting mechanism.
Push Security has found numerous related phishing pages impersonating various major brands, all following a similar Calendly-themed design.
Another variant of this phishing operation targets Facebook Business accounts, with over 31 URLs used to impersonate different companies over time. A third approach combines methods, targeting Google and Facebook accounts through Calendly-styled pages that generate BITB pop-ups.
This method obscures the real phishing server behind a fake URL bar, making it difficult for users to differentiate genuine login prompts from fraudulent ones. Additional anti-analysis measures, such as IP-based blocking, further complicate investigation efforts.
The focus on ad management accounts aligns with broader threat trends. Compromised Google Ads and Facebook Business accounts can be used for malvertising campaigns, distributing phishing links, malware, and fraud schemes, bypassing traditional email defenses.
By targeting Google Workspace for initial access and then ad platforms, the attackers can monetize and utilize stolen credentials directly or sell access to other malicious entities.
Based on reporting by GBHackers.
